← Back to browse · API

CVE-2022-2025

Severity
CRITICAL
CVSS
9.8
EPSS
0.04275
Risk score
40.7
CISA KEV
No
PoC
No
Published
2022-09-23
Modified
2025-05-22
First seen
2026-08-07
Aliases
EUVD-2022-34329, GHSA-3QJJ-8GWH-QXVC
Products
Grandstream:Grandstream GSD3710 1.0.11.13
Sources
euvd EUVD-2022-34329

Description

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.

References